identity assurance: when it matters david l. wasley internet2 / incommon

8
Identity Assurance: When it Matters David L. Wasley Internet2 / InCommon

Upload: kathlyn-charles

Post on 03-Jan-2016

221 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: Identity Assurance: When it Matters David L. Wasley Internet2 / InCommon

Identity Assurance:When it Matters

David L. Wasley

Internet2 / InCommon

Page 2: Identity Assurance: When it Matters David L. Wasley Internet2 / InCommon

2David L. Wasley

Service Providers rely on Identity Providers

• Basic InCommon IdP requirements are•Use best common practices•Publish what you do

• Some services need more formal rules•When there is risk if identity is wrong•Risks vary too …

Page 3: Identity Assurance: When it Matters David L. Wasley Internet2 / InCommon

3David L. Wasley

InCommon Enhanced Identity Services

• Identity assurance defined by sets of requirements and assessment criteria

• Initial 2 sets intended to satisfy Federal eAuthentication Levels 1 & 2

•See NIST Special Pub 800-63

•“Bronze” “Level 1”; “Silver” “Level 2”

• “Silver” will be required by NIH

Page 4: Identity Assurance: When it Matters David L. Wasley Internet2 / InCommon

4David L. Wasley

Identity Assurance Requirements

General areas to be considered include:

• Business, Policy and Operational Factors

• Identity Proofing

• Digital Electronic Credential Technology

• Credential Issuance and Management

Page 5: Identity Assurance: When it Matters David L. Wasley Internet2 / InCommon

5David L. Wasley

Identity Assurance Requirrements (cont.)

• Identity Information Management

• Security and Management of Authentication Events

• Identity Assertion Content•E.g. privacy issues …

• Technical Environment

Page 6: Identity Assurance: When it Matters David L. Wasley Internet2 / InCommon

6David L. Wasley

Identity Assurance Assessment

• Essentially an independent “audit”

• Criteria are defined by InCommon

• Assessor may be your Internal Auditor if that office is sufficiently independent

• External auditors may be used

• InCommon has -no- plans to do audits!

Page 7: Identity Assurance: When it Matters David L. Wasley Internet2 / InCommon

7David L. Wasley

Process will include

• Notify InCommon of intent• Have assessment performed• Provide (summary) of audit results• If acceptable, then InCommon will require an

addendum to the Participation Agreement• InCommon will add IdP qualifier(s) to metadata

• “Bronze” or both “Bronze” and “Silver”

• IdP then can include qualifiers in assertions•Mechanism yet T.B.D.

Page 8: Identity Assurance: When it Matters David L. Wasley Internet2 / InCommon

8David L. Wasley

Q & A ?